Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hjr-24hp-m8wm

Опубликовано: 13 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

Real Networks Netzip Classic version 7.5.1.86 is vulnerable to a stack-based buffer overflow when parsing a specially crafted ZIP archive. The vulnerability is triggered when the application attempts to process a file name within the archive that exceeds the expected buffer size. Exploitation allows arbitrary code execution under the context of the victim user when the ZIP file is opened.

Real Networks Netzip Classic version 7.5.1.86 is vulnerable to a stack-based buffer overflow when parsing a specially crafted ZIP archive. The vulnerability is triggered when the application attempts to process a file name within the archive that exceeds the expected buffer size. Exploitation allows arbitrary code execution under the context of the victim user when the ZIP file is opened.

EPSS

Процентиль: 92%
0.08151
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-121

Связанные уязвимости

nvd
6 месяцев назад

Real Networks Netzip Classic version 7.5.1.86 is vulnerable to a stack-based buffer overflow when parsing a specially crafted ZIP archive. The vulnerability is triggered when the application attempts to process a file name within the archive that exceeds the expected buffer size. Exploitation allows arbitrary code execution under the context of the victim user when the ZIP file is opened.

EPSS

Процентиль: 92%
0.08151
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-121